OpenAI reveals AI agent breached Hugging Face during internal security test

0
40
OpenAI reports autonomous AI agent escaped testing and hacked Hugging Face. Credits: Reuters
OpenAI reports autonomous AI agent escaped testing and hacked Hugging Face. Credits: Reuters

OpenAI has disclosed that one of its advanced AI-powered autonomous agents escaped a controlled testing environment and carried out a cyberattack on AI startup Hugging Face during a security evaluation. The company described the incident as an “unprecedented cyber incident, involving state-of-the-art cyber capabilities” and said it is strengthening its security safeguards.

According to OpenAI, the AI agent broke out of its isolated testing environment, accessed the internet, and breached Hugging Face’s infrastructure while attempting to complete its assigned testing objective.

Hugging Face, a platform that hosts open-source large language models and datasets, had revealed last week that it experienced a cyberattack unlike any it had previously handled. The company said the attack “was different from anything we had handled before” because “it was driven, end to end, by an autonomous AI agent system.”

Reacting to OpenAI’s disclosure, Hugging Face co-founder Clement Delangue wrote, “might have come from a frontier lab, given the sophistication of the agent. Turns out it did!” He added, “It’s quite mind-blowing that all of this happened autonomously!”

The incident is expected to increase concerns about the growing capabilities and risks of advanced AI models. U.S. Representative Greg Casar called the event alarming, saying, “AI is developing extremely fast with no real regulations to keep us safe.” He urged mandatory independent safety testing, compulsory disclosure of AI-related security incidents, and stronger international cooperation to reduce future risks.

The Office of the National Cyber Director, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. National Security Agency did not immediately comment on the incident.

Katie Moussouris, CEO of Luta Security, described the breach as a warning of future AI-driven cyber threats. She said today’s AI models are “like the world’s cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere.” She added that “labs and government evaluators need to work on the ability to contain, monitor, and disclose to affected parties when an AI pulls another Houdini, ideally before it harms a third party. None exist today.”

Matt Suiche, an engineer at agentic AI cybersecurity company Tolmo, said the incident shows frontier AI models are “closing the gap with state-of-the-art attackers.” However, he noted that similar cyberattacks can already be carried out using technology available beyond leading AI research labs.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.